Review found the `onTasksChanged` teardown reasoning inverted. The comment claimed every registration is an effect on the registry's own fiber, so listeners would be gone before service disposal empties the store — but the traceable proxy rebinds `this.ctx` to the CALLER, which this package's own HMR-safety test already proves. The only shipped consumer registers from the api-proxy mux stream, so it was still listening and simply kept the rows it last received. Service disposal now announces the emptied set, and teardown announces its stopping transition immediately instead of leaving an observer on `running` for however long a slow producer takes to release. Two documentation claims were false in the opposite direction: the Agent Note and the ui-task README both said an unowned task is invisible in the header, while `list(caller)` returns unowned tasks to every caller, the carrier fans their changes out to every subscribed session, and this PR's own test asserts exactly that. The note even contradicted itself two sections earlier. Both sides now state the real asymmetries — another session's tasks, and the process-local registry emptying on restart. The "no Web path calls the consuming `ctx.tasks.read()`" invariant claimed a test that did not exist; the carrier suite's producer had no `readOutput` at all, so a stray read would have failed nothing. Its producer now counts cursor consumption and the lifecycle and baseline paths both assert zero. Also: a session created after the mux opened now receives the task baseline it missed, the popover samples its clock when it opens rather than at mount, and a failed task's unbounded producer detail elides instead of widening the row.
Packages
English | 中文
Packages use the @deepseek-ai/dsh-* scope. Cordis Service subclasses and function plugins contribute through ctx.effect(), ctx.on(), or ctx.waterfall(). Authoring rules: package and root.
Hierarchy
Groups hold packages/<group>/<pkg>/; names stay @deepseek-ai/dsh-<pkg>. Group READMEs own package/ctx-key maps.
| Group | Role | Release expectation |
|---|---|---|
core/ |
Product API spine: sessions, prompts, tools, agent services, and the concrete loop | Product — stable surface |
api/ |
Remote BFF assembly and TypeRT RPC gateway | Product — stable surface |
typert/ |
Type graph generation, artifact loading, and runtime registry | Product — stable surface |
goal/ |
Same-session goal persistence and lifecycle | Product — stable surface |
feedback/ |
Human feedback | Product — stable surface |
llm/ |
LLM capability family: the abstract service + provider adapters | Product — stable surface |
e2b/ |
E2B providers | POC |
subprocess/ |
Subprocess capability family: Service Definition + local process-tree provider | Product — stable surface |
bash/ |
Bash capability family: executor seam, local impl, model-facing tool | Product — stable surface |
pty/ |
Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools | Product — stable surface |
code-runtime/ |
Code-execution capability family: Service Definition + worker-thread provider + Code Mode Consumer | Product — stable surface |
sandbox/ |
Process-confinement seam; bwrap/Landlock/Seatbelt backends | Product — stable surface |
fs/ |
Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools | Product — stable surface |
lsp/ |
LSP capability family: seam, generic stdio provider, and the lsp tool |
Product — stable surface |
skill/ |
Skill capability family: the provider registry, local provider, and model-facing catalog/loader | Product — stable surface |
compact/ |
Compaction capability family: Service Definition + basic provider + command Consumer | Product — stable surface |
context/ |
Model-visible request context, including workspace instructions and time context | Product — stable surface |
subagent/ |
Subagent capability family: the provider-registry contract and the model-facing delegation tool | Product — stable surface |
tasks/ |
Generic background-task runtime and model-facing task_* control tools |
Product — stable surface |
workflow/ |
Workflow seam, worker-thread engine, and model-facing workflow/ralph tools |
Product — stable surface |
web/ |
Web capability family: seam, search/fetch provider impls, and the model-facing web tools | Product — stable surface |
spill/ |
Spill capability family: storage seam, local impl, tool-result spill policy | Product — stable surface |
todo/ |
The model-facing todo_write tool |
Product — stable surface |
plan/ |
Plan collaboration state with a direct entry command and reviewed exit | Product — stable surface |
preset/ |
Per-session agent composition from preset cordis.yml files |
Product — stable surface |
guard/ |
Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer |
Product — stable surface |
bundle/ |
Installable dsh --profile patch layers |
Product — stable surface |
self-modification/ |
The agent modifies its own runtime: inspect the live runtime's plugins and services, mount/unmount model-written plugins (design) and restricted repository Plugin loading | Product — stable surface |
hooks/ |
Hook bridges + the shared Claude Code / Codex wire-protocol library | Product — stable surface |
session/ |
Durable session data plane: persistence seam + JSONL/SQLite backends, projection seam, log-backed titles, session reporting | Product — stable surface |
session-query/ |
Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search | Product — stable surface |
settings/ |
User-settings seam + file-backed provider | Product — stable surface |
credentials/ |
Credential-reference seam + env-over-.env provider |
Product — stable surface |
storage/ |
Non-session storage hub + backends + domain form | Product — stable surface |
workspace/ |
Workspace entity | Product — stable surface |
scaffold/ |
Create/launch/drive project tooling: helper, launcher, initializer, wire protocol with both ends, launcher telemetry | Product — stable surface |
acp/ |
Automation-only Agent Client Protocol server | Product — stable surface |
interaction/ |
Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool | Product — stable surface |
boot/ |
Shared app-bin boot glue | Product — stable surface |
host/ |
Web-GUI host half: API gateway + HTTP route server | Product — stable surface |
client/ |
Web-GUI browser half: shell, wire, object services, slots, ui-* plugins |
Product — stable surface |
experimental/ |
Prototypes and internal plugins | Unreleased |
examples/ |
Demo bundles (agent-spine + CLI/ACP/JSON-RPC bins) leaves load | Support — example infra |
support/ |
Support infrastructure (testkits, invariants, replay, Loader smokes) | Support — lower compatibility expectations |
util/ |
Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) |
Support — small, stable, harness-dep-free |
New packages join existing groups; new groups update their README and this table.
Dependencies
The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).
Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities separate Service Definition / Service provider / Consumer roles when they evolve independently; see capability seams.
Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.